Home / Data Protection Guidance and Insights / What Should a UK GDPR Privacy Notice Include?

What Should a UK GDPR Privacy Notice Include?

A good privacy notice does more than list legal requirements. It tells people, in clear language, what will happen to their information and gives the organisation an accurate record of its transparency decisions.

Did you know? Simply placing a privacy notice on a website is not be enough. Organisations should actively make people aware of the information and provide an easy way to access it at the point their data is collected or first used.

A privacy notice explains how an organisation collects, uses, shares and keeps personal information. It is a practical way of meeting the UK GDPR right to be informed and should reflect what the organisation actually does, not simply repeat legal wording.


What is the difference between a privacy notice and a privacy policy?

The terms are often used interchangeably, but the audience matters. A privacy notice is information for the people whose personal information you use. An internal data protection policy usually tells staff how the organisation manages data protection. Publishing an internal policy does not necessarily meet the right-to-be-informed requirements.


What should a UK GDPR privacy notice include?

The exact content depends on whether information is collected from the person or from another source, but a notice will commonly need to explain:

  • the organisation’s identity and contact details, and DPO contact details where applicable;
  • the purposes for which personal information is used and the lawful basis for each purpose;
  • the legitimate interests pursued where legitimate interests is relied upon;
  • the categories of personal information, particularly where it was obtained from another source;
  • who receives the information, including relevant categories of recipients;
  • international transfers and the safeguards used;
  • retention periods or the criteria used to decide them;
  • the rights available to people and how they can exercise those rights;
  • the right to complain to the organisation and to the ICO;
  • whether providing the information is a legal or contractual requirement and the consequences of not providing it; and
  • any solely automated decision-making or profiling that requires an explanation.


When should privacy information be provided?

When information is collected directly from a person, privacy information should be provided at the time it is obtained. When information comes from another source, it should generally be provided within a reasonable period and no later than one month, subject to the specific timing rules and any applicable exception.


A website notice may not be enough

Putting a privacy notice on a website can make it accessible, but people should be made aware of it at the relevant point. Application forms, customer sign-up journeys, recruitment systems, CCTV signage and telephone scripts may all need a short notice or a clear link to fuller information.


Use layered and just-in-time information

A long document is not always the clearest approach. A short first layer can explain the most important points, with links to detailed sections. Just-in-time messages can explain an unexpected use at the point a person provides particular information. The aim is for people to understand the real consequences of the processing.


Do we need different notices for different groups?

Often, yes. Employees, job applicants, customers, website users, suppliers and event attendees may have very different relationships with the organisation. Separate or carefully layered notices can be clearer than one document trying to cover every activity.


Keep the notice aligned with your records

Compare privacy notices with the organisation’s records of processing activities, retention schedule, contracts, cookie information and actual systems. Review the notice when you introduce a new purpose, supplier, technology, international transfer or significant change to retention. Bring material new uses to people’s attention before the processing begins.


See the ICO’s right-to-be-informed guidance for the detailed requirements.

Frequently asked questions


Does every organisation need a privacy notice?

Most organisations that collect or use personal information will need to provide privacy information. The format and level of detail should reflect the nature of the processing and the people affected.


Can we use one privacy notice for customers and employees?

It is possible, but it is often clearer to use separate notices because the purposes, lawful bases, recipients, retention periods and rights may differ significantly.


How often should a privacy notice be reviewed?

Review it regularly and whenever a material change occurs, such as a new system, purpose, supplier, data source, transfer arrangement or retention period.


Do we need consent to issue a privacy notice?

No. A privacy notice provides required information; it is not a consent form. If consent is the lawful basis for a particular activity, the consent request should still meet the separate UK GDPR standard.

Written by Clara Westbrook, solicitor and founder.


Speak to our team

This is a photo of alexander hazell, a data protection consultant at westbrook data protection services

Alexander Hazel

Consultant

Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights